Juniper bugged

Opinion
Jan 31, 20052 mins

* Juniper warns of vulnerabilities

Juniper last week warned M- and T-Series router customers that run releases of Junos software developed before Jan. 7 to upgrade the software or suffer a “serious security vulnerability.”   “This vulnerability could be exploited either by a directly attached neighboring device or by a remote attacker that can deliver certain packets to the router,” according to a Juniper Technical Bulletin obtained by Network World. “Routers running vulnerable Junos software are susceptible regardless of the router’s configuration. It is not possible to use firewall filters to protect vulnerable routers.”

Juniper last week warned M- and T-Series router customers that run releases of Junos software developed before Jan. 7 to upgrade the software or suffer a “serious security vulnerability.” 

“This vulnerability could be exploited either by a directly attached neighboring device or by a remote attacker that can deliver certain packets to the router,” according to a Juniper Technical Bulletin obtained by Network World. “Routers running vulnerable Junos software are susceptible regardless of the router’s configuration. It is not possible to use firewall filters to protect vulnerable routers.”

Juniper has assigned a risk level of “high” to this vulnerability. The bug is a blow to Juniper, which prides itself on the stability and reliability of its software, especially when compared with Cisco’s IOS.

All versions of Junos software built on or after Jan. 22 contain the modified code, the bulletin states, while software built between Jan. 7 and Jan. 22 might contain the modified code, depending on the specific Junos release.